From owner-freebsd-security Wed Nov 15 12:50:43 2000 Delivered-To: freebsd-security@freebsd.org Received: from citusc17.usc.edu (citusc17.usc.edu [128.125.38.177]) by hub.freebsd.org (Postfix) with ESMTP id AA33337B479 for ; Wed, 15 Nov 2000 12:50:39 -0800 (PST) Received: (from kris@localhost) by citusc17.usc.edu (8.11.1/8.11.1) id eAFKpnc21358; Wed, 15 Nov 2000 12:51:49 -0800 (PST) (envelope-from kris) Date: Wed, 15 Nov 2000 12:51:48 -0800 From: Kris Kennaway To: Rossen Raykov Cc: security@FreeBSD.ORG Subject: Re: problem using sysinstall Message-ID: <20001115125148.A21232@citusc17.usc.edu> References: <003f01c04f3e$3c77e170$4c00000a@sage> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="d6Gm4EdcadzBjdND" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <003f01c04f3e$3c77e170$4c00000a@sage>; from rraykov@sageian.com on Wed, Nov 15, 2000 at 02:57:08PM -0500 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --d6Gm4EdcadzBjdND Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Wed, Nov 15, 2000 at 02:57:08PM -0500, Rossen Raykov wrote: > My question is : is it normal to achieve such a results after this action? > Is the sysinstall behavior correct? Why there ware no warnings about changes > in /etc/passwd? > Is it normal the behavior on toor alias? Installing the bin distribution overwrites /etc (along with overwriting all other parts of the base system, like you asked it to). Live remote upgrades of a running system like this are dangerous for that reason. I did think sysinstall prompted for a root password, though. Even so, since you're installing on a multi-user system with logins enabled during the upgrade theres still a race condition before the password file is updated. Don't do that :-) Kris --d6Gm4EdcadzBjdND Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjoS92MACgkQWry0BWjoQKWnfgCguTF8SxmplZ9yx1flNgQe8N38 fxkAmwdjwwAwoB4raLlocc+UwIfmujJT =WJ3o -----END PGP SIGNATURE----- --d6Gm4EdcadzBjdND-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message